The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This attack affects only Chrome/Edge browsers
We have discovered 821,280 live websites that are affected by CVE-2025-4566.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 821,280 live websites (31% of Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 289 versions ( 80% of all versions) |
| 182,840 websites | |
| 79,841 websites | |
| 47,165 websites | |
| 39,030 websites | |
| 33,431 websites | |
| 31,878 websites | |
| 30,196 websites | |
| 27,757 websites | |
| 26,573 websites | |
| 22,171 websites |
| .com | 320,536 websites |
| .de | 44,148 websites |
| .com.br | 30,871 websites |
| .org | 28,821 websites |
| .it | 28,138 websites |
| .ru | 21,592 websites |
| .pl | 21,137 websites |
| .nl | 19,387 websites |
| .fr | 19,159 websites |
| .net | 17,088 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.io | *** | ||
| **************.de | *** | ||
| ************.com | *,*** | ||
| ***********.com | *,*** | ||
| ********.com | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| **.***.br | *,*** | ||
| ******.com | *,*** | ||
| *********.com | *,*** |
FAQ